Policy Number 19

 

Privacy Policy

 

At The Lugger we take the privacy and confidentiality of our guests and staff seriously and will do our utmost to protect them from any breach. The purpose of this policy is to let you know the ways we collect, use and share information through the site and in-house.

 

Scope:

 

We work to protect information from loss, misuse or unauthorized alteration by using industry recognized security safeguards, coupled with a range of other security procedures and practices. We maintain physical, electronic and procedural safeguards that comply with applicable laws.

 

While we take certain physical, electronic and administrative measures to protect confidentiality of information, due to the nature of internet, we cannot guarantee that all the information will remain secure. By submitting information to this site, you agree that you are aware of these risks. If you do not wish to submit your information electronically do not do so. The staff and Owners are not responsible for any consequence of illegal or unauthorized acts by third parties, including but not limited to hacking or similar crimes.

 

Our policies permit employees to access information only on a need-to-know basis. We educate our employees on the importance of confidentiality and customer privacy. Employees who violate our policy will be subject to disciplinary process.

 

We do not reveal customer information to any external organization unless we have previously informed the customer in disclosure or agreement (such as in this Privacy policy) or agreement have been authorized by the customer, or are required by law. We will not record personal or sensitive information when you visit our website unless you enter the information voluntarily.

 

Whenever we hire other organizations to provide support services, we require them to conform to our privacy standards and to allow us to audit them for compliance.

 

We have the following procedure in place:

 

  • There are two computers on the premises, one in the office and one at the Reception and both are located in locked rooms when not attended.

 

  • Both computers are accessed by PIN numbers and only authorized staff are allowed to operate the computers.

 

  • Although the computers in the office and Reception are networked Reception staff cannot access sensitive documents such as Staff database, wages, references and suppliers details without further secure PIN number and only the Manager, Bookkeeper and the Owner has access to these information.

 

  • Both computers are protected by antivirus software and staff are allowed to use the computers for business purposes only.

 

  • Both computers turn off if left unattended for two minutes and passwords are needed to re-activate them.

 

  • Staff are not allowed to store their own private documents / information on any computer.

 

  • Due to the nature of our business we do keep customers and suppliers information on our computers. All customer booking details are shredded at the end of each calendar month. Suppliers’ information are only accessed by the Bookkeeper, Manager and the Owner and the computer is protected by secure password.

 

  • We are Payment Card Industry Data Security Standard (PCI-DSS) compliant and our work is audited annually.

 

The Information we collect:

 

Staff (Some or all of the following) :

Name, address, Date of Birth, e-mail address, telephone number, previous employment  record, sickness and absences records, references, medical certificate/s, disciplinary record, wage record, qualification and copies of work- related certificates, next-of-kin (minors’), copies of passport and driving license, CRB and criminal conviction records, nationality, Job application form and CV, letter of appointment and correspondence.

 

Customer and Supplier (some of the following but not all):

 

Name, address, telephone number/s, credit/debit card details, bank account details, historical patronage and / or trading, products prices, car registration number, nationality and passport number (non-UK Resident).

 

We use the information above for the smooth running of our business and for legal reason. We also use these information to communicate with our customer and supplier and to promote our business.

 

 

R Nubeebuckus

May 2018

 

Who we are

Our website address is: https://theluggerinn.co.uk.

What personal data we collect and why we collect it

Comments

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

 

Cookies

If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you have an account and you log in to this site, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracing your interaction with the embedded content if you have an account and are logged in to that website.

Analytics

How long we retain your data

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.